The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Moz Pro
    4. My website was hacked last Thursday

    My website was hacked last Thursday

    Moz Pro
    5 3 560
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NileCruises
      NileCruises last edited by

      My business website was hacked (for the 2nd time in 12 months) last Thursday and all data lost. I've been rebuilding the site and database since then but I'm still getting Hacking Warnings each day.

      The latest warning says:

      Dear Colin/Administrator,
      Someone has attempted to inject SQL into your domain:
            HACK DETECTED!
        PHP TYPE
            IP: 94.100.17.134
        Scriptname: /index.cfm
        PathInfo: /index.cfm
        QueryString: src=http%3A%2F%2Fpicasa.com.oprst.in%2Fshow.php%3Fid%3D16907217

      My Technical advisro tells me the IP address is that of Inferno Solutions of The Netherlands.

      I wonder if anyone has suffered hacking like this what steps they too and what I could do about the potential hackers?

      Colin

      1 Reply Last reply Reply Quote 0
      • RyanKent
        RyanKent last edited by

        What I could do about the potential hackers?

        A few tips:

        • If you are using any software on your site, ensure you keep up with the latest version. Normally you do not have to run out and update the moment a new release comes out, but you should have a plan in place to always update within 90 days of any release.

        • Ensure you share any passwords with the fewest number of people possible. You, your web developer and possibly your SEO consultant are the only ones which may need access to your web server. If anyone with a password changes (i.e. employee leaves, developer changes, etc) then change your password.

        • Do not use an easy to guess password such as "admin1" or "password1". Actually, both your username and password should be difficult to guess.

        • Do not use shared server hosting. If you are paying $10 or less per month for hosting, you are on a shared server. Upgrade to VPS or better. VPS hosting starts at around $35 but there are numerous advantages over shared hosting.

        • Use a service such as Verisign (now Symantec) to perform daily malware scans. If you purchase a Verisign SSL certificate, the service comes with the package.

        • Each type of hosting (Apache, nginx, Microsoft, etc) and website will have its own security recommendations. Make sure they are followed. On my dedicated server, there are some security scripts which have been written by my web host to enhance security. Additionally, there is code I add to the htaccess file on all sites which block common attacks.

        With all of the above in mind, nothing can beat a thorough security check from an expert. There are companies that focus web security as their business. Such inspections are very expensive but they offer a lot of value. Also know that even the biggest companies in the world suffer security breaches. By following all of the above steps, you will clearly be a more difficult target then many other sites whereas right now it sounds like you are an easy target.

        Good Luck.

        1 Reply Last reply Reply Quote 4
        • NileCruises
          NileCruises last edited by

          Thanks for those tips and the advice Ryan.

          I will take your advice and look at adding Verisign too.

          I'm getting the site back into shape but have noticed a dip in ranking from 5th (after the last hack when we were 1st) to 7th today.

          Hopefully the need to rebuild a lot of the data including titles and descriptions might help me in the long run to create a better site.

          Thanks again for your time and help.

          Colin

          Trustico 1 Reply Last reply Reply Quote 0
          • Trustico
            Trustico @NileCruises last edited by

            Hi Colin,

            Just an additional note, Verisign (now Symantec) - as well as performing daily malware scans - has a fantastic range of SSL certificates that encrypts your customers' info when using forms and for online payments.  I noticed in your contact page that the connection is not secure.

            http://www.trustico.co.uk/products/symantec/secure_site/symantec-secure-site-ssl-certificates.php

            I've sent a link for a basic domain validated certificate, but if you want a green bar at the top of your website so your customers know that you are whom you say then have a look at the EV (extended validation) certificates.

            Nice website, by the way, I'd love a Nile cruise!

            Sarah.

            NileCruises 1 Reply Last reply Reply Quote 1
            • NileCruises
              NileCruises @Trustico last edited by

              Thanks very much Sarah and thanks for the link and recommendations. I'll look into it today.

              Plus the Extended Validation.

              That's really kind of you.

              Kind regards,

              Colin

              1 Reply Last reply Reply Quote 0
              • 1 / 1
              • First post
                Last post
              • How can i increase DA of my website?
                Mubashirsqw
                Mubashirsqw
                0
                5
                103

              • Does MOZ still do deep crawls of the website?
                kaydeeweb
                kaydeeweb
                0
                2
                72

              • Tags on my website cause duplicate content
                TomVolpe
                TomVolpe
                0
                4
                131

              • Website disappeared from Google :(
                eyepaq
                eyepaq
                0
                5
                1.2k

              • Problem in doing seo for a German medical website?
                Andropenis_Australia
                Andropenis_Australia
                0
                3
                390

              • How to force SeoMoz to re-crawl my website?
                KeriMorgret
                KeriMorgret
                0
                4
                2.0k

              • My Website is not being crawled by Google last 15 days
                KeriMorgret
                KeriMorgret
                0
                4
                1.5k

              • How to track with SEOMOZ a website in several language
                Marcus_Miller
                Marcus_Miller
                1
                4
                999

              Get started with Moz Pro!

              Unlock the power of advanced SEO tools and data-driven insights.

              Start my free trial
              Products
              • Moz Pro
              • Moz Local
              • Moz API
              • Moz Data
              • STAT
              • Product Updates
              Moz Solutions
              • SMB Solutions
              • Agency Solutions
              • Enterprise Solutions
              • Digital Marketers
              Free SEO Tools
              • Domain Authority Checker
              • Link Explorer
              • Keyword Explorer
              • Competitive Research
              • Brand Authority Checker
              • Local Citation Checker
              • MozBar Extension
              • MozCast
              Resources
              • Blog
              • SEO Learning Center
              • Help Hub
              • Beginner's Guide to SEO
              • How-to Guides
              • Moz Academy
              • API Docs
              About Moz
              • About
              • Team
              • Careers
              • Contact
              Why Moz
              • Case Studies
              • Testimonials
              Get Involved
              • Become an Affiliate
              • MozCon
              • Webinars
              • Practical Marketer Series
              • MozPod
              Connect with us

              Contact the Help team

              Join our newsletter
              Moz logo
              © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
              • Accessibility
              • Terms of Use
              • Privacy